Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Magic Kitten

Also known as: Group 42, VOYEUR

Description

Earliest activity back to November 2008. An established group of cyber attackers based in Iran, who carried on several campaigns in 2013, including a series of attacks targeting political dissidents and those supporting Iranian political opposition.

AI Analysis

· 1 week ago

Executive Summary

Magic Kitten, also known as Group 42 and VOYEUR, is a cyber threat actor likely based in Iran with historical ties to politically motivated attacks, particularly targeting dissidents and opposition supporters since at least 2013.

Goals & Targeting

Magic Kitten's strategic objectives appear to be tied to maintaining influence and control over domestic and regional politics, particularly within Iran. The group focuses on targeting sectors related to politics, civil society, and individuals associated with opposing views or activities against the Iranian government. Their victims are often high-value targets such as activists, journalists, and political dissidents, suggesting a focus on silencing opposition through cyber means.

Enhanced Description

Magic Kitten is an established cyberattack group with roots dating back to November 2008. The group has been linked to multiple campaigns targeting political dissidents, activists, and individuals supporting Iranian political opposition. Operating primarily from Iran, Magic Kitten employs a range of tactics that align with state-sponsored or politically motivated cyber espionage. Their activities have been noted for their focus on gathering intelligence and disrupting political opponents through compromising digital communications and infrastructure.

Key Capabilities

  • Spear-phishing
  • Malware deployment
  • Persistent threat campaigns
  • Social engineering

Campaigns & Victims

Magic Kitten's campaign patterns suggest a focus on long-term, patient attacks to infiltrate and compromise targets. Their operational tempo appears sporadic but consistent with politically motivated campaigns in the region. Notable historical operations include targeted phishing campaigns and malware deployment against opposition figures, though specific details remain limited due to sparse reporting.

IOC Patterns

  • Spear-phishing emails targeting political activists
  • Use of custom or known malware variants
  • Compromise of communication platforms

Recommended Actions

  • Implement rigorous email filtering and threat detection mechanisms
  • Monitor for suspicious activities in internal communication channels
  • Conduct regular employee training on social engineering tactics

Suggested Tags

espionage
中东 politics
state-sponsored
cyber espionage

Confidence Assessment

Low. The available data on Magic Kitten is minimal and fragmented, with much of the information derived from indirect intelligence linking to similar groups or activities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

espionage
中东 politics
state-sponsored
cyber espionage

Details

Type
Unknown
Country of Origin
I
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.